Impact
The hid-rmi driver in the Linux kernel allocates read and write buffers solely based on the report descriptor received from a HID device, without enforcing a minimum size. This allows an attacker to supply a device with an undersized report descriptor that triggers reads and writes beyond the allocated memory boundaries. vulnerability exposes kernel heap contents to unprivileged userspace and the device, and can corrupt adjacent memory, potentially leading to kernel crashes or further exploitation. The driver also fails to terminate the read loop on zero‑length replies, which can cause prolonged blocking of system resources.
Affected Systems
All systems running the Linux kernel that include the rmi HID driver before the patch are affected. The vulnerability applies to all vendor implementations of the Linux kernel, regardless of distribution. No specific version numbers are listed in the data, so any kernel build that has not yet incorporated the fix is vulnerable.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity impact on confidentiality and integrity. The EPSS score of less than 1% shows a very low but non‑zero likelihood of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The attack surface is local: an attacker must provide a HID device with an undersized report descriptor, which can be achieved through a standard USB interface or a built‑in embedded controller. Successful exploitation would allow memory disclosure and potential corruption, but no remote or network‑based attack vectors are described.
OpenCVE Enrichment
Debian DLA
Debian DSA